Trojan

Trojan.Win64.Shelma.raw removal

Malware Removal

The Trojan.Win64.Shelma.raw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Shelma.raw virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to modify proxy settings

How to determine Trojan.Win64.Shelma.raw?


File Info:

name: 5FE2DBB04610B7558583.mlw
path: /opt/CAPEv2/storage/binaries/76950783958455947be9181ce2c347ce528e1836f4956e4d2ec070301edb9953
crc32: FEC7FBCB
md5: 5fe2dbb04610b75585839f95729cdd63
sha1: dddee68989a37bbe54d7e5839b64393036dd8288
sha256: 76950783958455947be9181ce2c347ce528e1836f4956e4d2ec070301edb9953
sha512: 4250c5446e2d3985a81f2e7a1d4147b5dc5b9fec602483869b095f4abd25b2fc56ceb30cac51a9362e1f410345f8b8fbdfdbc611d01abbd7d5a5574b3b9e0a5d
ssdeep: 6144:QvZXI8N1IjEro37LfUF97C7KU7gZ9Nd822twNJJJ655ZZo7lS:MZXIqmeo37eakNd2n
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1D0941733A676FCA6FA5DB0F0F8A5C9622D6C6D630123707932B7F3782A775509B04291
sha3_384: adbac9bc7da59e1145e67c262c17b90bb9e46b46b824b434d8f274996daaf34b48c1f83bd453c8b1c5c082000e566f1f
ep_bytes: 554889e54883ec30c745fcff00000048
timestamp: 2021-12-06 01:34:09

Version Info:

0: [No Data]

Trojan.Win64.Shelma.raw also known as:

DrWebTrojan.MulDrop19.12298
MicroWorld-eScanTrojan.GenericKD.47574513
FireEyeGeneric.mg.5fe2dbb04610b755
McAfeeRDN/Generic BackDoor
MalwarebytesTrojan.Crypt
ZillyaTrojan.Shelma.Win64.7046
K7AntiVirusTrojan ( 0058b6d81 )
AlibabaTrojan:Win64/Shelma.bee1a57e
K7GWTrojan ( 0058b6d81 )
Cybereasonmalicious.989a37
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/GenKryptik.FOAF
TrendMicro-HouseCallBackdoor.Win64.SWRORT.YXBLGZ
Paloaltogeneric.ml
KasperskyTrojan.Win64.Shelma.raw
BitDefenderTrojan.GenericKD.47574513
AvastWin64:TrojanX-gen [Trj]
Ad-AwareTrojan.GenericKD.47574513
EmsisoftTrojan.GenericKD.47574513 (B)
TrendMicroBackdoor.Win64.SWRORT.YXBLGZ
McAfee-GW-EditionRDN/Generic BackDoor
IkarusTrojan.Win64.Crypt
GDataTrojan.GenericKD.47574513
WebrootW32.Trojan.Dropper
AviraHEUR/AGEN.1205986
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4802250
VBA32Backdoor.Cobalt
ALYacTrojan.GenericKD.47574513
MAXmalware (ai score=87)
FortinetPossibleThreat.MU
AVGWin64:TrojanX-gen [Trj]
PandaTrj/CI.A

How to remove Trojan.Win64.Shelma.raw?

Trojan.Win64.Shelma.raw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment